I am running Splunk Enterprise 8.0.6 and have HadoopDataRoll configured, using Hadoop 3.2.1 with Java 1.8.0_282-b08. I have a virtual index configured to archive an index to AWS S3. The HadoopData...
I have an indexer cluster with a replication factor of 3. If I were to implement HadoopDataRoll, would only one copy of each event be archived to Hadoop at freeze time, or would all three bucket c...
We use the Splunk HadoopDataRoll to move our frozen data over to our Hadoop cluster. The writing of the data to HDFS seems to work pretty well, but the searching of it through Splunk d...
Hi,
I'm searching for the documentation for the new 6.5 hadoopdataroll feature, and unable to find it. Can someone point me to it? Or where it's setup within Splunk? Nothing obvious stands o...
...opied as per below doc.
https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Automatearchiving
Im planning to use HadoopDataRoll to send the splunk index data to Hadoop for longer R...
Documentation says Archive indexer data to meet your data retention policies without using valuable indexer space.
How exactly does this help Splunk indexers? Does Hadoop has more compression r...
...Roll?
I believe Hadoop Connect exports search results and HadoopDataRoll send the raw data journal.gz
Can I use Hadoop Techniques like Hive, Pig..etc for analytics on the archived data sent t...
We currently have our Splunk environment running on Server 2012. I've built out an Hadoop cluster in *NIX and currently building a *NIX box for Hadoop Analytics. Will I be able to rolldata from o...
Looking at new 6.5 Hadoopdataroll feature - will the bucket reader be able to read this data? Also, would it be possible to export the "raw data", but keep the tstats?